Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-12-12 CVE-2024-54110 Unspecified vulnerability in Huawei Harmonyos 5.0.0
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
network
low complexity
huawei
7.5
2024-12-12 CVE-2024-54111 Unspecified vulnerability in Huawei Harmonyos 5.0.0
Read/Write vulnerability in the image decoding module Impact: Successful exploitation of this vulnerability will affect availability.
network
low complexity
huawei
7.5
2024-12-12 CVE-2024-54112 Unspecified vulnerability in Huawei Harmonyos 5.0.0
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
network
low complexity
huawei
7.5
2024-12-12 CVE-2024-54113 Unspecified vulnerability in Huawei Harmonyos 5.0.0
Process residence vulnerability in abnormal scenarios in the print module Impact: Successful exploitation of this vulnerability may affect power consumption.
network
low complexity
huawei
7.5
2024-12-12 CVE-2024-54114 Out-of-bounds Read vulnerability in Huawei Harmonyos 5.0.0
Out-of-bounds access vulnerability in playback in the DASH module Impact: Successful exploitation of this vulnerability will affect availability.
network
low complexity
huawei CWE-125
7.5
2024-12-12 CVE-2024-54115 Out-of-bounds Read vulnerability in Huawei Harmonyos 5.0.0
Out-of-bounds read vulnerability in the DASH module Impact: Successful exploitation of this vulnerability will affect availability.
network
low complexity
huawei CWE-125
7.5
2024-12-12 CVE-2024-54116 Out-of-bounds Read vulnerability in Huawei Harmonyos 5.0.0
Out-of-bounds read vulnerability in the M3U8 module Impact: Successful exploitation of this vulnerability may cause features to perform abnormally.
network
low complexity
huawei CWE-125
7.5
2024-12-12 CVE-2024-54117 Unspecified vulnerability in Huawei Harmonyos 5.0.0
Cross-process screen stack vulnerability in the UIExtension module Impact: Successful exploitation of this vulnerability may affect service confidentiality.
network
low complexity
huawei
7.5
2024-12-12 CVE-2024-11760 The Currency Converter Widget ? PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'currency-converter-widget-pro' shortcode in all versions up to, and including, 1.0.6 due to insufficient input sanitization and output escaping on user supplied attributes.
network
low complexity
CWE-79
6.4
2024-12-12 CVE-2024-12160 The Seraphinite Bulk Discounts for WooCommerce plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.4.6.
network
low complexity
CWE-79
6.1